Year: 2025

Fortinet OS & FortiProxy Authentication Bypass Vulnerability (CVE-2024-55591) Notification

January 16, 2025

Overview Recently, NSFOCUS CERT detected that Fortinet has issued a security notification and fixed the identity authentication bypass vulnerability in FortiOS and FortiProxy (CVE-2024-55591). Unauthenticated attackers can bypass system identity authentication by sending special packets to the Node.js websocket module, thus obtaining super administrator permissions of the target system. The CVSS score is 9.8. At […]

Alert of Buffer Overflow Vulnerabilities in Multiple Ivanti Products (CVE-2025-0282)

January 10, 2025

Overview Recently, NSFOCUS detected that Ivanti issued a security announcement and fixed buffer overflow vulnerabilities (CVE-2025-0282) in several products of Ivanti. Due to the stack-based buffer overflow in Ivanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA Gateways, an unauthenticated attacker can trigger a buffer overflow by sending specially crafted packets allowing arbitrary […]

Key Events of 2024 for NSFOCUS WAF

January 8, 2025

Summarizing the past, embracing the future. Let’s take a recap at the key events of NSFOCUS WAF in 2024. Market Recognition Market share: From 2019 to 2023, NSFOCUS WAF has been ranked 1st in China’s WAF hardware market share. March 2024: Recognized by Forrester, a leading market research company, for our outstanding Bot Management capabilities. […]

Windows LDAP Denial of Service Vulnerability (CVE-2024-49113) Alert

January 7, 2025

Overview Recently, NSFOCUS CERT detected that the details of Windows LDAP remote code execution vulnerability (CVE-2024-49113) were disclosed. Due to an out-of-bounds read vulnerability in wldap32.dll of Windows LDAP service, an unauthenticated attacker can induce a target server (as an LDAP client) to initiate a query request to a malicious LDAP server controlled by the […]

Coming Soon! NSFOCUS Will Enhance DDoS Protection Capabilities in New Version of ADS Products

January 3, 2025

We are excited to announce the upcoming release of the ADS V4.5R90F06 version, which brings significant enhancements to our DDoS protection capabilities. The update focuses on bringing more precise DDoS mitigations. This new version improves existing algorithms with an emphasis on advanced technology and usability. Key New Features: 1. DNS Protection Enhancements: DNS Protection Algorithm […]

Search

Subscribe to the NSFOCUS Blog